4.9 • 696 Ratings
🗓️ 23 June 2020
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, June 23rd, 2020 edition of the Sansonet Storm Center's Stormcast. |
0:07.2 | My name is Johannes Orich, and the day I'm recording from Jacksonville, Florida. |
0:13.4 | DDA today has a nice introduction to Winmerch and, well, for a change, no, it's not a Python script. |
0:20.8 | It's actually GUI software that runs on Windows and allows you to easily compare to office documents. |
0:30.1 | Well, you may say, Word has a feature where I can compare to documents and look at what was edited, that's not what Winmerge is about. |
0:40.3 | It actually compares the internal XML structure of the documents, metadata, and the like. |
0:47.1 | So a lot more thorough than just comparing like what the text may have changed between two |
0:53.3 | documents. |
0:54.7 | Where it is make them in handy, for example, is quite often we see with spearfishing |
1:00.2 | attacks where an attacker uses an existing document that someone has published, for example, |
1:06.2 | on their website, and then add some malicious payload to it. |
1:10.5 | Of course, with Winmerge, if you do have that |
1:14.6 | original document available, it may be really easy to then pull out what is the malicious |
1:20.2 | component that the attacker added. On patched Tuesday two weeks ago, I was a little bit surprised |
1:27.3 | that my Mac never prompted me for any of the Microsoft Office updates. |
1:34.2 | And I didn't really pay too much attention, I have to admit, but it turns out that Microsoft was a little bit late in actually releasing the updates for Microsoft Office on the Mac. |
1:47.1 | They now, and actually last week they did that, but still delayed, have released updates |
1:53.8 | for four vulnerabilities in Microsoft Office for the Mac. Three of these vulnerabilities can |
2:00.7 | actually lead to remote code execution. |
2:04.0 | So definitely make sure you apply them. |
2:07.7 | Also, while we're talking about the Mac, VMware also has released an update for |
2:12.9 | VMware Tools for Mac OS. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.